First published: Tue Jan 23 2007(Updated: )
BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the JDBCDataSourceFactory MBean Properties, which allows local administrative users to read the cleartext password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BEA Weblogic Server | =8.1 | |
BEA Weblogic Server | =9.0 | |
BEA Weblogic Server | =7.0 | |
BEA Weblogic Server | <=8.1 | |
BEA Weblogic Server | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.